Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add CSP nonce #69

Open
Shadowfaxenator opened this issue Nov 11, 2024 · 7 comments
Open

Add CSP nonce #69

Shadowfaxenator opened this issue Nov 11, 2024 · 7 comments
Labels
enhancement New feature or request security

Comments

@Shadowfaxenator
Copy link

Please support CSP inline scripts, we need to add nonce automatically at render time for all page inline scripts.

@maddalax
Copy link
Owner

Not a bad idea, I'll add it to the backlog

@maddalax maddalax added enhancement New feature or request security labels Nov 11, 2024
@gedw99
Copy link

gedw99 commented Nov 21, 2024

Also got hit with this , so +1

@rafaelDev0ps
Copy link
Contributor

rafaelDev0ps commented Nov 26, 2024

hey @maddalax do you mind if I PR this?

@maddalax
Copy link
Owner

hey @maddalax do you mind if I PR this?

Not at all, go ahead!

@rafaelDev0ps
Copy link
Contributor

@maddalax @gedw99 should we keep this optional (enabled by default in the configs) or keep immutable?

@gedw99
Copy link

gedw99 commented Nov 27, 2024

I would make it a config toggle, but up to @maddalax as he knows more about the roadmap etc...

@maddalax
Copy link
Owner

Let's make it optional for now since it technically is a breaking change. I can make it default in a new major version

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request security
Projects
None yet
Development

No branches or pull requests

4 participants